5.5
CVSSv2

CVE-2018-16838

Published: 25/03/2019 Updated: 29/05/2023
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject sssd -

redhat enterprise linux 7.0

Vendor Advisories

Debian Bug report logs - #931432 sssd: CVE-2018-16838 Package: src:sssd; Maintainer for src:sssd is Debian SSSD Team <pkg-sssd-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 4 Jul 2019 19:21:01 UTC Severity: grave Tags: security, upstream Found in versions sssd/115 ...
Synopsis Moderate: sssd security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for sssd is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ( ...
Synopsis Low: sssd security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic An update for sssd is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base scor ...
Synopsis Important: Red Hat Virtualization security update Type/Severity Security Advisory: Important Topic An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Impo ...
A flaw was found in sssd Group Policy Objects implementation When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access(CVE-2018-16838) A vulnerability was found in sssd where, if a user was configured with no home directory set, sssd ...
A flaw was found in sssd Group Policy Objects implementation When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access(CVE-2018-16838) A vulnerability was found in sssd where, if a user was configured with no home directory set, sssd ...